Application of Risk-Based Approach - Anti Money Laundering / Countering Financing of Terrorism (AML/CFT)
Application of Risk-Based Approach
Risk Assessment
Paragraph 10.2.1 of the Policy Document, requires reporting institutions to identify, assess and understand their ML/TF risk in relation to the following parameters:
- customers;
- countries or geographical areas;
- products, services, transactions or delivery channels; and
- other relevant risk factors.
Reporting institutions’ first IRA must be comprehensive, covering all the above mentioned parameters i.e. customers, countries/geographical areas and products/ services/ transactions and delivery channel, at minimum. Reporting institutions may choose to update the IRA on a thematic basis.
Reporting institutions may consider to set the frequency of the IRA on a specific period e.g. every 1 to 2 years or where circumstances have changed that may warrant a refresh of the IRA, e.g. material changes in risk profile, significant internal audit finding, changes in business direction, new typologies suggested by authorities or the Financial Action Task Force (FATF), or when embarking in new technologies, etc.
Reporting institutions may also refer to the guidance documents on risk-based approach available in Appendix 1 of the Policy Document and guidance issued by the FATF which are available on its website at: http://www.fatf-gafi.org
Risk Profiling
Reporting institutions are to assess the customers’ risk based on the type of customer, geographical location, products, services, transactions or delivery channels and other relevant factors (such as emerging threats, trends, change in behaviours, past suspicious transaction report experience, etc.).
Reporting institutions are expected to consider the applicable factors at the stage of on-boarding and during re-rating to determine the risk of a customer. Reporting institutions are also expected to document internal customer risk profiling assessments, for record keeping and audit purposes.
Reporting institutions may refer to the guidance provided in Appendix 1 of the Policy Document for suggested approach to conduct customer risk profiling.
Reporting institutions can rely on various indicators in deciding to rate a customer as having higher risk. Reporting institutions are expected to consider all risk factors applicable based on type of customer, geographical location, products, services, transactions or delivery channels and may include other relevant factors such as patterns of transactions or activity throughout the business relationship.
However, there are instances where a customer is classified as having higher risk based on only one higher risk indicator regardless of the level of risk posed by the other factors. For example, a customer must be classified as having higher risk if the customer is a foreign politically exposed person (PEP); or is from higher risk countries that are called for by the FATF. In both examples above, enhanced CDD shall apply.
